{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/cloudlinux7els/vex/2026/cve-2026-0394-els_os-cloudlinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-03T13:43:09Z",
      "generator": {
        "date": "2026-08-03T13:43:09Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-0394-ELS_OS-CLOUDLINUX7ELS",
      "initial_release_date": "2026-03-27T09:16:00Z",
      "revision_history": [
        {
          "date": "2026-03-27T09:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-01T22:18:51Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-03T13:43:09Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-0394"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "CloudLinux 7",
                "product": {
                  "name": "CloudLinux 7",
                  "product_id": "CloudLinux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:cloudlinux:cloudlinux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "CloudLinux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-devel@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-pgsql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-mysql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-devel@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-pigeonhole@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot@2.2.36-8.el7.tuxcare.els2?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-devel@2.2.36-8.el7.tuxcare.els2?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot@2.2.36-8.el7.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-pgsql@2.2.36-8.el7.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-mysql@2.2.36-8.el7.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-devel@2.2.36-8.el7.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/dovecot-pigeonhole@2.2.36-8.el7.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-0394",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users.  Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CloudLinux-7:dovecot-1:2.2.36-8.el7.i686",
          "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
          "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
          "CloudLinux-7:dovecot-1:2.2.36-8.el7.x86_64",
          "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.i686",
          "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
          "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
          "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
          "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
          "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
          "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
          "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
          "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
          "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-0394"
        },
        {
          "category": "external",
          "summary": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json",
          "url": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
        }
      ],
      "release_date": "2026-03-27T09:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-03T11:32:59.477087Z",
          "details": "This issue only triggers under a non-default Dovecot setup that uses per‑domain passwd-file lookups with a path derived from %d and either places those files at an unsafe base path (resolving near /etc) or explicitly allows “/” in usernames. Even if reachable over the network, the impact is limited to reading a passwd‑suffixed file (for example /etc/passwd), which on modern Linux does not contain password hashes and yields no code execution or privilege escalation, aligning with the CVSS’s confidentiality‑only impact. In centrally managed server/VM deployments that don’t rely on such per‑domain passwd files or keep them under dedicated directories (e.g., /etc/dovecot/auth/%d), the preconditions are absent and, with no known public exploit, practical risk is minimal.",
          "product_ids": [
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.i686",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.i686",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.i686",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.i686",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els2.x86_64",
            "CloudLinux-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}